It was discovered that Apache HTTP Server's mod_ldap module incorrectly handled memory when processing per-directory configurations. A remote attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-29167)
It was discovered that Apache HTTP Server's mod_proxy_ftp module incorrectly handled HTML generation for FTP directory listings. A remote attacker could possibly use this issue to inject arbitrary web script or HTML. (CVE-2026-29170)
Nitescu Lucian discovered that Apache HTTP Server's mod_auth_digest module was vulnerable to a timing attack. A remote attacker could possibly use this issue to bypass Digest authentication. (CVE-2026-33006)
2.4.7-1ubuntu4.22+esm152.4.18-2ubuntu3.17+esm202.4.29-1ubuntu4.27+esm112.4.41-4ubuntu3.23+esm6